CVE-2024-35248

Summary

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Affected Software

VendorProductVersion RangeStatus
MicrosoftMicrosoft Dynamics 365 Business Central 2023 Release Wave 122.0.0 < 23.0.18933affected
MicrosoftMicrosoft Dynamics 365 Business Central 2023 Release Wave 223.0.0 < 23.0.18933affected
MicrosoftMicrosoft Dynamics 365 Business Central 2024 Release Wave 124.0 < 24.0.19487affected

Weaknesses

  • CWE-1390: CWE-1390: Weak Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

CVE Program Container

Additional References

References